pkcs11-keygen.docbook revision a7d4d528749aa403397b3e2260abf2046a0cfa7b
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt [<!ENTITY mdash "&#8212;">]>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt<!--
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt - Copyright (C) 2009, 2014 Internet Systems Consortium, Inc. ("ISC")
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt -
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt - Permission to use, copy, modify, and/or distribute this software for any
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt - purpose with or without fee is hereby granted, provided that the above
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt - copyright notice and this permission notice appear in all copies.
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt -
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt - PERFORMANCE OF THIS SOFTWARE.
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt-->
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt<refentry id="man.pkcs11-keygen">
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <refentryinfo>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <date>January 15, 2014</date>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt </refentryinfo>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <refmeta>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <refentrytitle><application>pkcs11-keygen</application></refentrytitle>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <manvolnum>8</manvolnum>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <refmiscinfo>BIND9</refmiscinfo>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt </refmeta>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <refnamediv>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <refname><application>pkcs11-keygen</application></refname>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <refpurpose>generate keys on a PKCS#11 device</refpurpose>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt </refnamediv>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <docinfo>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <copyright>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <year>2009</year>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <year>2014</year>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt </copyright>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt </docinfo>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <refsynopsisdiv>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <cmdsynopsis>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <command>pkcs11-keygen</command>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <arg choice="req">-a <replaceable class="parameter">algorithm</replaceable></arg>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <arg><option>-b <replaceable class="parameter">keysize</replaceable></option></arg>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <arg><option>-e</option></arg>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <arg><option>-i <replaceable class="parameter">id</replaceable></option></arg>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <arg><option>-m <replaceable class="parameter">module</replaceable></option></arg>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <arg><option>-P</option></arg>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <arg><option>-p <replaceable class="parameter">PIN</replaceable></option></arg>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <arg><option>-q</option></arg>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <arg><option>-S</option></arg>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <arg><option>-s <replaceable class="parameter">slot</replaceable></option></arg>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <arg choice="req">label</arg>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt </cmdsynopsis>
</refsynopsisdiv>
<refsect1>
<title>DESCRIPTION</title>
<para>
<command>pkcs11-keygen</command> causes a PKCS#11 device to generate
a new key pair with the given <option>label</option> (which must be
unique) and with <option>keysize</option> bits of prime.
</para>
</refsect1>
<refsect1>
<title>ARGUMENTS</title>
<variablelist>
<varlistentry>
<term>-a <replaceable class="parameter">algorithm</replaceable></term>
<listitem>
<para>
Specify the key algorithm class: Supported classes are RSA,
DSA, DH, and ECC. In addition to these strings, the
<option>algorithm</option> can be specified as a DNSSEC
signing algorithm that will be used with this key; for
example, NSEC3RSASHA1 maps to RSA, and ECDSAP256SHA256 maps
to ECC. The default class is "RSA".
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-b <replaceable class="parameter">keysize</replaceable></term>
<listitem>
<para>
Create the key pair with <option>keysize</option> bits of
prime. For ECC keys, the only valid values are 256 and 384,
and the default is 256.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-e</term>
<listitem>
<para>
For RSA keys only, use a large exponent.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-i <replaceable class="parameter">id</replaceable></term>
<listitem>
<para>
Create key objects with id. The id is either
an unsigned short 2 byte or an unsigned long 4 byte number.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-m <replaceable class="parameter">module</replaceable></term>
<listitem>
<para>
Specify the PKCS#11 provider module. This must be the full
path to a shared library object implementing the PKCS#11 API
for the device.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-P</term>
<listitem>
<para>
Set the new private key to be non-sensitive and extractable.
The allows the private key data to be read from the PKCS#11
device. The default is for private keys to be sensitive and
non-extractable.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-p <replaceable class="parameter">PIN</replaceable></term>
<listitem>
<para>
Specify the PIN for the device. If no PIN is provided on
the command line, <command>pkcs11-keygen</command> will
prompt for it.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-q</term>
<listitem>
<para>
Quiet mode: suppress unnecessary output.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-S</term>
<listitem>
<para>
For Diffie-Hellman (DH) keys only, use a special prime of
768, 1024 or 1536 bit size and base (aka generator) 2.
If not specified, bit size will default to 1024.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-s <replaceable class="parameter">slot</replaceable></term>
<listitem>
<para>
Open the session with the given PKCS#11 slot. The default is
slot 0.
</para>
</listitem>
</varlistentry>
</variablelist>
</refsect1>
<refsect1>
<title>SEE ALSO</title>
<para>
<citerefentry>
<refentrytitle>pkcs11-destroy</refentrytitle><manvolnum>8</manvolnum>
</citerefentry>,
<citerefentry>
<refentrytitle>pkcs11-list</refentrytitle><manvolnum>8</manvolnum>
</citerefentry>,
<citerefentry>
<refentrytitle>pkcs11-tokens</refentrytitle><manvolnum>8</manvolnum>
</citerefentry>,
<citerefentry>
<refentrytitle>dnssec-keyfromlabel</refentrytitle><manvolnum>8</manvolnum>
</citerefentry>
</para>
</refsect1>
<refsect1>
<title>AUTHOR</title>
<para><corpauthor>Internet Systems Consortium</corpauthor>
</para>
</refsect1>
</refentry><!--
- Local variables:
- mode: sgml
- End:
-->